Privacy
This is a template, and this page is starter copy: true for what the repository does out of the box, and short on purpose. It is not a policy written for any real company, because there is no company behind this starter.
What the public site collects
Nothing. The marketing and knowledge pages set no analytics cookies, load no third-party trackers, and talk to no ad tech. The optional providers the starter can wire up (Sentry, PostHog, Turnstile) ship disabled and stay inactive until a deployment configures them.
What a deployment stores
An instance stores account details, hashed credentials, sessions, workspaces, memberships and audit records in its own Cloudflare D1 database. Private Assistant Conversations store questions and saved answers in that deployment’s Durable Objects. A configured model provider receives the authorized conversation context needed to answer. Personal exports include currently authorized conversations; Workspace exports exclude them. No template vendor receives this data.
Local development
The demo fixtures and starter-lab Workspace run in your environment, using memory or persisted local D1 and Durable Object storage. With external providers disabled, the demo sends no generated data to those providers.
Before you ship
A real product needs a real policy: your legal entity, the providers you actually enable, retention windows, and the jurisdictions you operate in. Replace this page before your first real user arrives.